Can internal PinePhone firmware be compromised?
#1
Perhaps a stupid question. Is there any firmware in PinePhone which could be compromised by the OS? For example, I heard that a compromised OS on a laptop can compromise BIOS, which makes the computer insecure without recurse (and you won't know it unless you have Anti Evil Maid).

Let's say I install some untrusted OS on the eMMC, use it, then wipe it. After that I boot from a trusted microSD, can I be sure that I am not compromised?

I am also thinking about such a use case: I have untrusted OS on the eMMC, where I collect all the viruses I want. When I need to do something security-critical (e.g., open my email), I insert a microSD with a bootable trusted OS, use it and then remove the microSD again returning to the initial untrusted OS. Would such access to the email be secure?
#2
All software available to the public can be compromised, and unless it's something almost nobody uses, all software will be compromised at some point in time.
Privacy, security, and freedom is never ethernal, and it's never a gift.
Both the consumer and developer have to fight for it forever.
#3
The firmware in the Quectel modem can be changed and therefore it can also be corrupted.

I have not heard of any way how the bootloader could be compromised?
If that is not the case, eMMC always can be cleaned.
#4
(11-18-2020, 02:16 PM)fsflover Wrote: Let's say I install some untrusted OS on the eMMC, use it, then wipe it. After that I boot from a trusted microSD, can I be sure that I am not compromised?

Unlike regular computers, ARM systems have all the bios-y info stored on the emmc/sdcard, as @LinAdmin2 pointed out the modem has it's own firmware,  but that can be reflashed as well.
#5
Would there be a way to lock down modem firmware with a dip switch seems like a major target
owo notices your distro.
#6
(11-18-2020, 06:07 PM)evilbunny Wrote:
(11-18-2020, 02:16 PM)fsflover Wrote: Let's say I install some untrusted OS on the eMMC, use it, then wipe it. After that I boot from a trusted microSD, can I be sure that I am not compromised?

Unlike regular computers, ARM systems have all the bios-y info stored on the emmc/sdcard,
Wrong;
The ARM system must have some initial loader to start reading from eMMc or sd.card.
#7
(11-19-2020, 11:03 AM)LinAdmin2 Wrote:
(11-18-2020, 06:07 PM)evilbunny Wrote:
(11-18-2020, 02:16 PM)fsflover Wrote: Let's say I install some untrusted OS on the eMMC, use it, then wipe it. After that I boot from a trusted microSD, can I be sure that I am not compromised?

Unlike regular computers, ARM systems have all the bios-y info stored on the emmc/sdcard,
Wrong;
The ARM system must have some initial loader to start reading from eMMc or sd.card.

I'm led to believe boot is hard coded into the chip. The rest is on emmc/sdcard.
#8
https://linux-sunxi.org/Pine64#Boot_sequence
https://linux-sunxi.org/BROM#A64


Possibly Related Threads…
Thread Author Replies Views Last Post
  PinePhone earpiece too quiet Waffelo 3 300 01-01-2025, 09:41 PM
Last Post: Kevin Kofler
Question WhatsApp & Pinephone - What are the alternatives for collaborative comms? danimations 15 18,964 12-27-2024, 03:02 AM
Last Post: biketool
  eSIM on PinePhone just_a_q 9 5,400 12-25-2024, 04:16 AM
Last Post: zetabeta
  US Mobile, via T-Mobile, won't support Pinephone Pro - SOLVED, SIMPLY jovval 13 7,196 12-05-2024, 04:38 PM
Last Post: tllim
  Pinephone compatibility with Telstra, now that 3 G shutdown and 5 G available tracyanne 0 211 12-04-2024, 10:53 PM
Last Post: tracyanne
  Want to buy second hand PinePhone 3G version rudi.timmermans 0 375 11-01-2024, 09:58 AM
Last Post: rudi.timmermans
  Can use PlayStation on Pinephone? willharper 6 6,076 10-30-2024, 08:07 AM
Last Post: biketool
  Ordered PinePhone till today have no info or confirmation about order hennadiyt 1 558 10-05-2024, 02:20 PM
Last Post: KC9UDX
  How can I record video on a Pinephone? kk22 18 8,142 07-22-2024, 05:18 PM
Last Post: baptx
  Pinephone not booting, always vibrating alexander12 8 7,433 07-19-2024, 07:50 PM
Last Post: Blackheart

Forum Jump:


Users browsing this thread: 3 Guest(s)